Wiping the phone is mandatory for three of the five Android enrollment methods. Decide before the purchase order goes out.
Wiping the device is a precondition for corporate-owned work profile, for fully managed, and for dedicated device enrollment. The personally owned work profile is the one route that skips it. Settle which method applies while the handsets are still on a purchase order and the rollout is uneventful; settle it afterward and somebody has to explain why four hundred phones already in use are about to be erased.

- Factory resetRequired for three of the five methods
- 15 devicesEnrollment limit for a standard account
- 1,000 devicesLimit with a device enrollment manager
- DeprecatedDevice administrator, on Google services devices
Factory reset, and which methods require one.
Microsoft publishes this as a table, and it is the single fact that should govern your enrollment choice before a device is bought or handed out.
- Nothing gets erased under two routes: the Android Enterprise personally owned work profile, and the deprecated device administrator method. Because a phone somebody is already using can take either one, personally owned work profile is the realistic answer whenever the employee owns the hardware.
- Three routes start with a wipe: corporate-owned work profile, fully managed, and dedicated devices. All three assume company ownership, and all three mean anything currently in an employee's hands has to be erased before it can reach that state.
- A second published detail deserves attention. Devices enrolling without a reset start pulling Intune policy straight away, and any setting you have not configured in Intune beforehand simply stays as it was. The device carries its previous configuration in with it.
- The practical upshot is that the decision belongs at the purchasing stage. When hardware is bought and distributed before anyone picks an enrollment method, the fleet usually ends up on the wrong one, because no organization is willing to erase hundreds of phones that people already use and keep personal data on.
Eight facts that shape how an Android deployment goes.
The factory reset requirement, which shapes everything
The published position leaves no ambiguity: corporate-owned work profile, fully managed and dedicated device enrollment each begin with wiping the handset. Personally owned work profile does not, and neither does the deprecated device administrator route. A stack of sealed boxes and a fleet already in people's pockets are therefore two completely different projects, which is why the choice belongs to procurement rather than to whoever configures the console later.
The work profile route for hardware the employee bought
A separate work profile is created on the employee's own handset so personal and work applications sit side by side and switch easily and securely, with the owner running enrollment from the Company Portal. Your authority stops at the applications and data inside that profile. Nothing gets wiped to set it up, which is precisely why this is the route that works on phones people already carry.
Corporate-owned work profile, for company phones people also use personally
Microsoft frames this one as corporate hardware that is also approved for personal use, with a distinct work profile the employee moves in and out of. It fits the common American arrangement where the company buys the phone and nobody seriously expects it to stay work-only. In our experience it is the method most organizations ought to be running and comparatively few actually are.
Fully managed, for devices that are only for work
Corporate hardware dedicated entirely to work, with a single associated user. Microsoft notes that this method opens up management of the whole device along with policy controls the work profile route cannot reach. The exchange is genuine: you gain that control and you give up any space for personal use, which people will attempt regardless unless the policy is stated plainly and the culture backs it.
Dedicated devices, for the ones nobody personally owns
Single-purpose and kiosk hardware owned by the company, with digital signage, ticket printing and inventory management named directly as the intended uses. You constrain which applications and web links exist and keep the device from being used for anything outside its assigned job, which describes an enormous amount of the equipment on American shop floors, loading docks and hotel front desks.
AOSP methods, for devices with no Google services at all
Corporate hardware built on the Android Open Source Project without Google Mobile Services has two routes of its own. One covers userless devices with nobody assigned, meant to be shared the way equipment in a library or lab is shared. The other ties a device to one person for work-only use. Ruggedized and purpose-built handsets land here constantly.
Zero-touch, which Microsoft recommends for volume
For bulk enrollment, and for getting remote staff onto managed devices without a technician in the room, zero-touch is the recommended approach: hardware is staged in advance so that powering it on provisions and enrolls it as fully managed automatically. Any company shipping phones to employees scattered across the country is choosing between this and paying somebody to touch every handset.
Device administrator is deprecated, and it is time to move
On any handset with access to Google Mobile Services, device administrator management is deprecated and no longer available, and Microsoft's guidance is to move to one of the other Android options. What remains is support and documentation covering some Android 15 and earlier devices that lack Google services. If your Android fleet still sits on this method, the migration is something to schedule rather than postpone.
Four decisions that separate a smooth Android deployment from a painful one.
We choose the enrollment method before devices are bought
Because corporate-owned work profile, fully managed and dedicated all start with a wipe, making the call during procurement means hardware shows up and enrolls correctly the first time. Leave it until later and the options narrow to erasing phones people already depend on, with the personal-data conversation that follows, or accepting a method that delivers less than the licensing entitles you to.
Company handsets usually belong on the corporate-owned work profile
Microsoft positions it for company hardware that is also approved for personal use, with a separate work profile the employee switches between. Pretending an American company phone will only ever be used for work produces either resentment or a second handset in the same pocket. This method is the configuration that matches reality while still leaving you genuine control.
We stage bulk enrollment correctly, account ceilings included
Fifteen devices is the ceiling on an ordinary non-administrator account; a device enrollment manager account reaches a thousand. Hitting that wall at device sixteen, midway through staging a shipment, is an entirely preventable afternoon. Where the supplier supports it, zero-touch is Microsoft's recommended answer for volume and for remote staff.
We schedule the exit from device administrator instead of postponing it
Deprecated and unavailable on handsets with Google Mobile Services, with Microsoft advising a move to another option, device administrator is a method with no future. Fleets still sitting on it are running out of road. Scheduling the move to Android Enterprise on your own timetable costs considerably less than being pushed into it by a hardware refresh nobody planned.
Six US situations where Android management decisions matter.
Logistics and delivery operations with rugged handsets
Barcode scanners, driver handsets and hardened field units, a great many of which ship without Google Mobile Services. The Android Open Source Project routes exist for exactly this hardware, userless where devices are shared and user-associated where one person keeps one unit. Choose correctly and you have a managed fleet; choose otherwise and you have equipment nobody can patch or lock.
Retail and hospitality with single-purpose devices
Menu boards, ticket printers, ordering terminals and stock-count units, all named in the dedicated device use cases. Restricting which applications and web links exist, and blocking anything outside the assigned job, is what keeps a customer-facing tablet from quietly becoming a general-purpose browser on the counter.
A company phone fleet where personal use is a fact
Company-purchased Android handsets that employees also use personally, which is how company phones function in the real world. Corporate-owned work profile was designed for this exact case, keeping work applications and data separate and governable while leaving the personal side untouched, and it avoids the fiction a fully managed deployment would require.
A regulated firm needing control over company devices
Where GLBA, the FTC Safeguards Rule, HIPAA or an insurance policy demands real authority over corporate hardware, fully managed enrollment delivers control of the entire device plus policy options the work profile route does not expose. In exchange personal use disappears, and that has to be published as policy rather than discovered by an employee whose photo app vanished.
A large distribution of new devices to remote staff
Hundreds of handsets heading to people in different states who will never set foot in an office. Zero-touch is the recommended answer for exactly this: stage the hardware ahead of time and each device provisions and enrolls as fully managed the moment its new owner powers it on. Otherwise somebody is unboxing every unit before it ships.
An estate still on Android device administrator
Deprecated on anything carrying Google Mobile Services, with documentation surviving only for certain Android 15 and earlier devices that lack Google services. The destination is not in question and there is no alternative route, so pairing the migration with a planned hardware refresh is far cheaper than executing it against a deadline somebody else sets.
How Android devices actually get managed in US organizations.
| Feature | Right method, chosen first | Whatever avoided a wipe | Unmanaged or device administrator |
|---|---|---|---|
Enrollment method matches device ownership | Yes | No | No |
Bulk enrollment through zero-touch | Yes | Rarely | No |
Full device policy control where owned | Yes | No | Partly |
Personal data separated from work data | Yes | Yes | No |
Kiosk and single-use devices locked down | Yes | No | No |
Devices without Google services supported | Yes, via AOSP | No | No |
On a supported management method | Yes | Yes | Deprecated |
Enrollment restrictions configured | Yes | Rarely | No |
Bulk enrollment limits understood | Yes | Discovered at device 16 | Not applicable |
How common this is in practice | Uncommon | Common | Common |
Every enrollment route, the hardware it fits, and whether it erases the handset.
Method
Personally owned work profile
- Suits, and whether a reset is required
- Employee-owned handsets in BYOD scenarios. Nothing is erased.
Method
Corporate-owned work profile
- Suits, and whether a reset is required
- Company hardware that is also approved for personal use. Wipe first.
Method
Fully managed
- Suits, and whether a reset is required
- Company hardware, work only, one user each, deepest policy control. Wipe first.
Method
Dedicated device
- Suits, and whether a reset is required
- Kiosk and single-purpose units, signage, ticket printing, inventory. Wipe first.
Method
AOSP userless
- Suits, and whether a reset is required
- Shared hardware with no Google services and nobody assigned. Rugged and purpose-built units.
Method
AOSP user associated
- Suits, and whether a reset is required
- Hardware without Google services, tied to one person, work only.
Method
Zero-touch enrollment
- Suits, and whether a reset is required
- The recommended path for bulk and remote staff, provisioning as fully managed at first power-on.
Method
Device administrator
- Suits, and whether a reset is required
- Deprecated, and unavailable wherever Google Mobile Services are present. Schedule the migration.
Five steps, and step one sets the price of everything after it.
- 1
Choose the enrollment method per population
Employee-owned handsets, company phones that double as personal ones, work-only hardware, single-purpose units and devices without Google services each resolve differently. This step lands before procurement or distribution, because three of the methods cannot be applied later without erasing the device.
- 2
Connect managed Google Play and set restrictions
The managed Google Play connection is a hard prerequisite for every Android Enterprise option. With that in place, configure enrollment restrictions by platform, version, manufacturer or ownership type, set device limits, and add terms and conditions if you want them presented in the Company Portal before anyone enrolls.
- 3
Prepare bulk enrollment properly
Zero-touch wherever the supplier offers it, since it is the recommended route for volume and for remote staff. Device enrollment manager accounts wherever hardware is staged centrally, given that an ordinary non-administrator account stops at fifteen devices while a device enrollment manager reaches a thousand.
- 4
Build the policy set for each method
Available controls differ between work profile, fully managed and dedicated device enrollment, so configuration profiles, compliance rules and application assignments have to be authored per method. Writing one policy set for a method it was never designed for is the usual origin of the complaint that Android management does not work.
- 5
Pilot, then distribute
Start with a small group spanning every method in scope and walk the enrollment experience end to end, including what the employee sees inside the Company Portal. The report covering incomplete and abandoned enrollments shows where people stalled, and it is worth reading during the pilot rather than after the fleet has shipped.
What organizations ask about Android Enterprise.
Fifteen questions worth answering first.
Choosing the method
- Who owns the devices?Everything else branches from this answer.
- Are the devices already in use?Three methods begin by erasing the handset.
- Is personal use allowed on company phones?This separates corporate-owned work profile from fully managed.
- Do the devices have Google Mobile Services?Without them, the AOSP routes are the only option.
- Are you still using device administrator?Deprecated wherever Google services are present.
Preparation
- Is Intune connected to managed Google Play?No Android Enterprise option works without it.
- Are devices currently enrolled elsewhere?Remove them from the incumbent platform first.
- Have you set enrollment restrictions?Available by platform, version, manufacturer or ownership.
- Do you need terms and conditions shown?They appear in the Company Portal ahead of enrollment.
- Should MFA apply at enrollment?Through Conditional Access, which needs Entra ID P1 or P2.
The practical limits
- How many devices is one person enrolling?Ordinary accounts stop at 15.
- Do you need a device enrollment manager?That account type reaches 1,000.
- Is zero-touch available from your supplier?The recommended route for volume and remote staff.
- Do you want devices auto-grouped by category?Categories drop devices into matching groups automatically.
- Who reviews abandoned enrollments?A report shows where people gave up partway.
The pages around this one.
Microsoft Intune
The platform underneath all of this, covering configuration, compliance and application delivery on every supported platform.
Kiosk and shared devices
A closer look at the dedicated device route: signage, terminals and shift-shared handhelds pinned to one job.
MDM solutions
The wider view across Windows, Apple and Android, and how to choose between the available approaches.
Settle the enrollment method while the phones are still on order.
Three of the five routes begin by erasing the handset, and that is not something you can retrofit onto hardware people already rely on. Thirty minutes spent on this at the purchasing stage avoids a conversation nobody enjoys having later.
Related Services
Explore more solutions that work great with this service